best-daybreak-48618
03/27/2025, 7:10 PMbest-daybreak-48618
03/28/2025, 1:30 AMmagnificent-energy-493
best-daybreak-48618
03/28/2025, 3:50 PMbest-daybreak-48618
03/28/2025, 3:50 PMbest-daybreak-48618
03/28/2025, 4:29 PMmagnificent-energy-493
magnificent-energy-493
magnificent-energy-493
magnificent-energy-493
dig +noall +answer <http://example.com|example.com> caa
if the response is empty good, if not either remove the CAA records or add pki.goog
if not added yetbest-daybreak-48618
03/28/2025, 6:21 PMbest-daybreak-48618
03/28/2025, 6:22 PMdig +noall +answer <http://auth.staging.sway.app|auth.staging.sway.app> caa
<http://auth.staging.sway.app|auth.staging.sway.app>. 1800 IN CNAME charming-lalande-c8jne8pfmu.projects.oryapis.com.
magnificent-energy-493
dig +noall +answer <http://sway.app|sway.app> caa
?stocky-king-5626
03/28/2025, 6:56 PMCAA records block issuance. Please remove all CAA records or add records for this authority (pki.goog)
stocky-king-5626
03/28/2025, 6:58 PM❯ dig <http://staging.sway.app|staging.sway.app> caa
; <<>> DiG 9.10.6 <<>> <http://staging.sway.app|staging.sway.app> caa
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39953
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;staging.sway.app. IN CAA
;; ANSWER SECTION:
<http://staging.sway.app|staging.sway.app>. 1799 IN CNAME <http://cname.vercel-dns.com|cname.vercel-dns.com>.
<http://cname.vercel-dns.com|cname.vercel-dns.com>. 1799 IN CAA 0 issue "<http://globalsign.com|globalsign.com>"
<http://cname.vercel-dns.com|cname.vercel-dns.com>. 1799 IN CAA 0 issue "<http://letsencrypt.org|letsencrypt.org>"
<http://cname.vercel-dns.com|cname.vercel-dns.com>. 1799 IN CAA 0 issue "<http://sectigo.com|sectigo.com>"
stocky-king-5626
03/28/2025, 7:01 PM<http://auth.staging.sway.app|auth.staging.sway.app>. IN CAA 0 issue "pki.goog"
stocky-king-5626
03/28/2025, 7:18 PMNote that the CA will always respect the CAA record closest to the domain name it is issuing a certificate for. So if you're requesting a cert for "www.community.example.org", the CA will check "www.community.example.org", then "community.example.org", then "example.org", stopping at the first CAA record it finds.
best-daybreak-48618
03/28/2025, 9:33 PMbest-daybreak-48618
03/28/2025, 10:24 PMstocky-king-5626
03/28/2025, 10:44 PMbest-daybreak-48618
03/28/2025, 10:54 PMbest-daybreak-48618
03/28/2025, 10:54 PMbest-daybreak-48618
03/28/2025, 10:54 PMstocky-king-5626
03/29/2025, 10:37 AM